OK, Combofix came up with 4 rootkit files, rebooted and found a whole bunch of things. Here's the log. I have a Hijack this log that was done after combofix was done. Let me know if you need to see it.
ComboFix 09-01-09.02 - Administrator 2009-01-09 22:33:36.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1015.647 [GMT -6:00]
Running from: c:\documents and settings\Administrator.EXPERIENCE\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrator.EXPERIENCE\Application Data\AntispywareBot
c:\documents and settings\Administrator.EXPERIENCE\Application Data\AntispywareBot\Log\2009 Jan 08 - 01_20_12 PM_343.log
c:\documents and settings\Administrator.EXPERIENCE\Application Data\AntispywareBot\Log\2009 Jan 08 - 01_59_32 PM_359.log
c:\documents and settings\Administrator.EXPERIENCE\Application Data\AntispywareBot\Log\2009 Jan 08 - 02_06_14 PM_515.log
c:\documents and settings\Administrator.EXPERIENCE\Application Data\AntispywareBot\Log\2009 Jan 08 - 07_46_28 PM_484.log
c:\documents and settings\Administrator.EXPERIENCE\Application Data\AntispywareBot\Log\2009 Jan 08 - 07_51_32 PM_625.log
c:\documents and settings\Administrator.EXPERIENCE\Application Data\AntispywareBot\Log\2009 Jan 08 - 11_10_33 AM_750.log
c:\documents and settings\Administrator.EXPERIENCE\Application Data\AntispywareBot\rs.dat
c:\documents and settings\Administrator.EXPERIENCE\Application Data\AntispywareBot\Settings\ScanResults.pie
c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Setup Wizard
c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Setup Wizard\SetupWizard.lnk
c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Setup Wizard\Uninstall SetupWizard.lnk
c:\program files\Antivirus 2009
c:\program files\Antivirus 2009\av2009.exe
c:\program files\Setup Wizard
c:\program files\Setup Wizard\settings.ini
c:\program files\Setup Wizard\SetupWizard.exe
c:\program files\Setup Wizard\Suicide_Girls_Flux.exe
c:\program files\Setup Wizard\unins000.dat
c:\program files\Setup Wizard\unins000.exe
c:\windows\system32\axxacamj.ini
c:\windows\system32\bczxwr.dll
c:\windows\system32\config\systemprofile\Desktop\Rapid Antivirus.lnk
c:\windows\system32\drivers\seneka.sys
c:\windows\system32\drivers\senekamaxxohqq.sys
c:\windows\system32\ffskkn.dll
c:\windows\system32\fiowncii.dll
c:\windows\system32\ieupdates.exe.tmp
c:\windows\system32\inldoh.dll
c:\windows\system32\ioaorrhr.ini
c:\windows\system32\nhpkkx.dll
c:\windows\system32\ofigvrno.dll
c:\windows\system32\ohrstktg.ini
c:\windows\system32\pmqeuf.dll
c:\windows\system32\rhrroaoi.dll
c:\windows\system32\rprslevn.dll
c:\windows\system32\seneka.dat
c:\windows\system32\senekaalktepbo.dll
c:\windows\system32\senekadf.dat
c:\windows\system32\senekalog.dat
c:\windows\system32\senekanftfqtsb.dll
c:\windows\system32\senekawqbwqvdy.dll
c:\windows\system32\tCIiknpo.ini
c:\windows\system32\tCIiknpo.ini2
c:\windows\system32\tdnqhtbp.dll
c:\windows\system32\TDSSoeqh.dll
c:\windows\system32\undvyxik.dll
c:\windows\system32\uniq.tll
c:\windows\system32\warning.gif
c:\windows\system32\win32hlp.cnf
c:\windows\system32\winsrc.dll
c:\windows\system32\ypsbtahb.ini
c:\windows\system32\yyhctcfx.ini
c:\windows\Tasks.\AntiSpywareBot Scheduled Scan.job
----- BITS: Possible infected sites -----
hxxp://childhe.com.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_SENEKA
((((((((((((((((((((((((( Files Created from 2008-12-10 to 2009-01-10 )))))))))))))))))))))))))))))))
.
2009-01-09 22:36 . 2009-01-09 22:36 <DIR> d-------- c:\windows\system32\oobe
2009-01-09 22:36 . 2009-01-09 22:36 <DIR> d-------- c:\windows\srchasst
2009-01-09 22:36 . 2009-01-09 22:36 <DIR> d-------- c:\windows\pchealth
2009-01-09 14:11 . 2009-01-09 14:13 <DIR> d-------- c:\program files\RegCure
2009-01-09 01:22 . 2009-01-09 04:12 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2009-01-09 01:22 . 2009-01-09 04:11 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2009-01-09 01:12 . 2009-01-09 01:12 <DIR> d-------- c:\program files\Trend Micro
2009-01-07 18:32 . 2009-01-07 18:32 73,216 --a------ c:\windows\system32\ffkuz.dll
2009-01-06 02:24 . 2009-01-06 02:24 111,616 --a------ c:\windows\system32\dllcache\userinit.exe
2009-01-02 12:58 . 2009-01-02 12:58 134,656 --a------ c:\windows\ipokozehu.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-09 20:06 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\avg7
2009-01-09 05:22 --------- d-----w c:\documents and settings\Administrator.EXPERIENCE\Application Data\BitTorrent
2009-01-06 08:24 111,616 ----a-w c:\windows\system32\userinit.exe
2008-12-20 03:50 --------- d-----w c:\program files\BitTorrent
2008-11-20 04:08 --------- d--h--r c:\documents and settings\Administrator.EXPERIENCE\Application Data\yahoo!
2008-04-07 06:59 67,696 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2008-04-07 06:59 54,376 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-04-07 06:59 34,952 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2008-04-07 06:59 46,720 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-04-07 06:59 172,144 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
.
------- Sigcheck -------
2007-06-08 06:00 360576 c7be59b07c6eb74bea6fd67c1b164015 c:\windows\system32\drivers\tcpip.sys
2009-01-06 02:24 111616 67412a22840f827b42bf5c7df8ea16f5 c:\windows\system32\userinit.exe
2009-01-06 02:24 111616 67412a22840f827b42bf5c7df8ea16f5 c:\windows\system32\dllcache\userinit.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2007-06-08 15360]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Jdecapaqekojoto"="c:\windows\ipokozehu.dll" [2009-01-02 134656]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-27 98304]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-27 118784]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-27 77824]
"AVG7_CC"="c:\progra~1\Grisoft\AVG7\avgcc.exe" [2008-10-21 590848]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SkyTel"="SkyTel.EXE" [2007-06-15 c:\windows\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [2007-07-05 c:\windows\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="c:\progra~1\Grisoft\AVG7\avgw.exe" [2008-03-01 219136]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2006-10-17 c:\windows\system32\advpack.dll]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"MemCheckBoxInRunDlg"= 1 (0x1)
"StartMenuFavorites"= 0 (0x0)
"Start_ShowHelp"= 0 (0x0)
"Start_ShowMyComputer"= 1 (0x1)
"Start_ShowMyDocs"= 1 (0x1)
"Start_ShowMyMusic"= 0 (0x0)
"Start_ShowRun"= 1 (0x1)
"Start_ShowSearch"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoSMMyPictures"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"MemCheckBoxInRunDlg"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoSMMyPictures"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"MemCheckBoxInRunDlg"= 1 (0x1)
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=pmqeuf.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\program files\\Grisoft\\AVG7\\avginet.exe"=
"c:\\program files\\Grisoft\\AVG7\\avgamsvr.exe"=
"c:\\program files\\Grisoft\\AVG7\\avgcc.exe"=
"c:\\program files\\Grisoft\\AVG7\\avgemc.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\program files\\Chron X\\ChronX.exe"=
"c:\\program files\\EA Games\\Command & Conquer The First Decade\\Command & Conquer Renegade(tm)\\Renegade\\Game.exe"=
"c:\\program files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\program files\\Yahoo!\\Messenger\\YServer.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"123:UDP"= 123:UDP:SNTP
--- Other Services/Drivers In Memory ---
*NewlyCreated* - HELPSVC
NETSVCS REQUIRES REPAIRS - current entries shown6to4
AppMgmt
AudioSrv
Browser
CryptSvc
DMServer
DHCP
EventSystem
FastUserSwitchingCompatibility
HidServ
Ias
Iprip
Irmon
LanmanServer
LanmanWorkstation
Netman
Nla
Ntmssvc
NWCWorkstation
Nwsapagent
Rasauto
Rasman
Remoteaccess
Schedule
Seclogon
SENS
Sharedaccess
Tapisrv
Themes
TrkWks
W32Time
WZCSVC
Wmi
WmdmPmSp
winmgmt
xmlprov
BITS
wuauserv
ShellHWDetection
WmdmPmSN
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
.
Contents of the 'Scheduled Tasks' folder
2009-01-09 c:\windows\Tasks\mwbndasx.job
- c:\windows\system32\rundll32.exe [2007-06-08 06:00]
2009-01-10 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2008-11-27 12:55]
2009-01-09 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2008-11-27 12:55]
.
- - - - ORPHANS REMOVED - - - -
BHO-{037C7B8A-151A-49E6-BAED-CC05FCB50328} - c:\windows\system32\winsrc.dll
BHO-{b6482342-291a-46d4-b031-dc60630e2afd} - c:\windows\system32\pmqeuf.dll
HKU-Default-Run-msiexec.exe - msiconf.exe
ShellExecuteHooks-{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - (no file)
Notify-byXNeDwu - byXNeDwu.dll
MSConfigStartUp-7043401d - c:\windows\system32\gtktsrho.dll
MSConfigStartUp-Ckucohuxe - c:\windows\Vkehir.dll
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.geocities.com/eastcentralpc/index.htmluSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page =
hxxp://www.google.comuSearchURL,(Default) =
hxxp://www.google.com/keyword/%s
FF - ProfilePath - c:\documents and settings\Administrator.EXPERIENCE\Application Data\Mozilla\Firefox\Profiles\
0agtqydv.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.geocities.com/eastcentralpc/index.htmlFF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-01-09 22:36:24
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\progra~1\Grisoft\AVG7\avgamsvr.exe
c:\progra~1\Grisoft\AVG7\avgupsvc.exe
c:\progra~1\Grisoft\AVG7\avgemc.exe
.
**************************************************************************
.
Completion time: 2009-01-09 22:37:36 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-10 04:37:25
Pre-Run: 17,287,991,296 bytes free
Post-Run: 17,329,553,408 bytes free
267